Anonymous
2026-09-04 10:02:16
(1 day ago)
Scanner hitting /.env.save on ara-oman.com () — aaguard
Brute-Force
Port Scan
🇫🇷
SpaceHost-Server
2026-09-02 22:23:10
(3 days ago)
Brute-Force
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-02 21:59:04
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-01.
show less
Web App Attack
SSH
Hacking
🇫🇷
SpaceHost-Server
2026-09-01 22:22:54
(4 days ago)
Brute-Force
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-01 21:59:25
(4 days ago)
Auto-ban: >3000 req/min op 2026-09-01
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-01 13:50:36
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.228.204.91 (91.204.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.204.91 (91.204.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:50:31.655409 2026] [security2:error] [pid 12931:tid 12931] [client 35.228.204.91:35238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kameleonquilt.com"] [uri "/.env.production"] [unique_id "apbYJwfM4z2aNl8hAPnmGgAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 12:45:01
(4 days ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 12:32:10
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.228.204.91 (91.204.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.204.91 (91.204.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:32:07.216381 2026] [security2:error] [pid 25323:tid 25323] [client 35.228.204.91:59544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "caribeanvacationsturs.com.spyasociados.com"] [uri "/.env.prod"] [unique_id "apbFx7o1Sixjk5_xnV7OtAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 11:02:52
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.228.204.91 (91.204.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.204.91 (91.204.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:02:47.047749 2026] [security2:error] [pid 8821:tid 8821] [client 35.228.204.91:35920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.astrologydemo.com"] [uri "/.env.old"] [unique_id "apaw12eRAwAhKNrqj9nsowAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
macrob
2026-09-01 10:11:50
(4 days ago)
2026/09/01 10:11:49 [error] 2296395#2296395: *543916018 access forbidden by rule, client: 35.228.204 ...
show more
2026/09/01 10:11:49 [error] 2296395#2296395: *543916018 access forbidden by rule, client: 35.228.204.91, server: binixo.ro, request: "GET /.env HTTP/1.1", host: "admin.binixo.ro"
2026/09/01 10:11:49 [error] 2296395#2296395: *543916024 access forbidden by rule, client: 35.228.204.91, server: binixo.ro, request: "GET /.env.save HTTP/1.1", host: "admin.binixo.ro"
2026/09/01 10:11:49 [error] 2296394#2296394: *543916029 access forbidden by rule, client: 35.228.204.91, server: binixo.ro, request: "GET /.env.backup HTTP/1.1", host: "admin.binixo.ro"
...
show less
Web App Attack
🇮🇹
Inartis
2026-09-01 09:37:12
(4 days ago)
35.228.204.91 - - [01/Sep/2026:11:37:11 +0200] "GET /.env.backup HTTP/1.1" 404 5607 "-" "crusader-wo ...
show more
35.228.204.91 - - [01/Sep/2026:11:37:11 +0200] "GET /.env.backup HTTP/1.1" 404 5607 "-" "crusader-worker/1.0"
35.228.204.91 - - [01/Sep/2026:11:37:11 +0200] "GET /.env.prod HTTP/1.1" 404 5607 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
WebNiraj
2026-09-01 09:07:22
(4 days ago)
(mod_security) mod_security (id:949110) triggered by 35.228.204.91 (FI/Finland/91.204.228.35.bc.goog ...
show more
(mod_security) mod_security (id:949110) triggered by 35.228.204.91 (FI/Finland/91.204.228.35.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-01 08:49:49
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.228.204.91 (91.204.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.204.91 (91.204.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:49:44.306375 2026] [security2:error] [pid 29495:tid 29495] [client 35.228.204.91:39796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shipps.nmorganist.org"] [uri "/.env.prod"] [unique_id "apaRqG7vZHXEH5BZVet19gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Viveronese
2026-09-01 07:46:48
(4 days ago)
Wordpress vulnerability scanning
Web App Attack
Anonymous
2026-09-01 07:25:06
(4 days ago)
[ns65.kdns.gr] httpd-config-scan: sites=www.iason-ceramics.gr; logs=/var/log/httpd/domains/iason-cer ...
show more
[ns65.kdns.gr] httpd-config-scan: sites=www.iason-ceramics.gr; logs=/var/log/httpd/domains/iason-ceramics.gr.log; samples=/.env | /.env.old | /.env.dev
show less
Hacking
Web App Attack